CVE-2016-9591

CWE-416Use After Free11 documents7 sources
Severity
5.5MEDIUM
EPSS
0.5%
top 35.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9
Latest updateMay 13

Description

JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDjasper_project/jasper< 2.0.12
Ubuntujasper< 1.900.1-14ubuntu3.4+1
CVEListV5jasper_project/jasper2.0.12

Also affects: Debian Linux 8.0, Enterprise Linux 7.3, 7.4

🔴Vulnerability Details

3
GHSA
GHSA-j57x-xc7m-f43w: JasPer before version 22022-05-13
CVEList
CVE-2016-9591: JasPer before version 22018-03-09
OSV
CVE-2016-9591: JasPer before version 22016-12-16

📋Vendor Advisories

2
Ubuntu
JasPer vulnerabilities2017-05-18
Red Hat
jasper: use-after-free / double-free in JPC encoder2016-12-16

💬Community

5
Bugzilla
CVE-2016-9591 CVE-2016-9600 CVE-2016-10251 jasper: various flaws [fedora-all]2016-12-20
Bugzilla
CVE-2016-9591 CVE-2016-9600 CVE-2017-5503 CVE-2017-5504 CVE-2017-5505 mingw-jasper: various flaws [epel-7]2016-12-20
Bugzilla
CVE-2016-9591 CVE-2016-9600 CVE-2017-5503 CVE-2017-5504 CVE-2017-5505 mingw-jasper: various flaws [fedora-all]2016-12-20
Bugzilla
CVE-2016-9591 jasper: use-after-free / double-free in JPC encoder2016-12-20
Bugzilla
CVE-2016-9591 CVE-2016-9600 CVE-2017-5503 CVE-2017-5504 CVE-2017-5505 jasper: various flaws [epel-5]2016-12-20
CVE-2016-9591 (MEDIUM CVSS 5.5) | JasPer before version 2.0.12 is vul | cvebase.io